Atona/Security
Security

CASA validation.

Atona's handling of Google user data has been independently assessed under CASA. This page records what that assessment covers, who performed it, when it was carried out — and, just as importantly, what it does not claim.

What CASA is

CASA stands for Cloud Application Security Assessment. It is a security assessment framework published by the App Defense Alliance, and it is the route by which applications that request access to sensitive or restricted Google user data demonstrate that they handle it responsibly.

An assessment is carried out against a defined set of requirements at a defined assurance level. When it is completed successfully, the assessor issues a Letter of Validation — a scoped, dated document covering a named application, not an open-ended endorsement of the company that builds it.

The framework, its tiers, and its current requirements are published by the App Defense Alliance: appdefensealliance.dev/casa.

Atona's assessment

Taken from the Letter of Validation and the assessor's assessment record.

Assurance level
CASA Tier 2
Assessment method
Dynamic Application Security Testing (DAST) against the running web application.
Assessment date
27 April 2026
Authorized assessor
TAC Security, via its ESOF AppSec ADA CASA platform
Application covered
Atona — web application
Revalidation
CASA validations are time-limited and are renewed by reassessment. We publish the assessment date rather than an expiry, so that this page cannot quietly go stale — for current validity, ask [email protected].

Scope

A CASA assessment is deliberately bounded, and being specific about the boundary is part of taking it seriously. CASA is administered by the App Defense Alliance — it is an independent assessment, not a Google certification, endorsement, or partnership.

What it covers

  • The Atona web application, and its handling of the Google user data it accesses.
  • Assessment against the CASA Tier 2 requirements.
  • Dynamic testing of the running application, with findings remediated and revalidated before the letter was issued.
  • The application as it stood on the assessment date.

A point-in-time assessment says that a defined set of requirements was met on a defined date. It does not say nothing will ever go wrong. If you find a security issue, we would rather hear about it — see below.

Contact and related pages

Security contact
[email protected]

Report a suspected vulnerability or a compromised account to [email protected]. For how data is collected, retained, and deleted, see the privacy policy.